{"id":1145430,"url":"https://alion.io/job/geico-identity-security-distinguished-engineer","title":"Identity Security Distinguished Engineer","company":{"id":2667051,"name":"GEICO","domain":"geico.com","url":"https://alion.io/company/geico-3","size_band":"1001-5000","is_staffing_agency":false,"employer_type":"direct","is_intermediary":false,"listed_via":null,"ats_vendor":"Workday","truth_index":{"grade":"B","score":76,"open_postings":25,"ghost_share":0,"stale_share":0.96,"repost_share":0,"time_to_fill_p50_days":27,"computed_at":"2026-09-26T05:45:00Z"}},"role":"Security","role_family":"Security","seniority":"lead","employment_type":"full_time","work_mode":"on_site","remote_scope":null,"remote_scope_basis":null,"remote_working_hours":null,"hiring_geo_confidence":"structured","locations":["Palo Alto, United States","Richardson, United States","Seattle, United States","United States"],"countries":["US"],"hiring_countries":[],"hiring_countries_total":0,"salary":{"min":140000,"max":300000,"currency":"USD","period":"year","gross":null,"usd_annual":300000},"salary_estimate":null,"experience_years_min":8,"visa_sponsorship":false,"relocation_package":false,"has_equity":false,"technologies":[{"name":"Active Directory","optional":false},{"name":"AWS","optional":false},{"name":"Azure","optional":false},{"name":"GCP","optional":false},{"name":"IAM","optional":false},{"name":"LDAP","optional":false},{"name":"Python","optional":false},{"name":"Rest API","optional":false},{"name":"Windows","optional":false}],"status":"live","first_seen_at":"2026-09-09T00:00:00Z","employer_posted_date":"2026-09-09","last_verified_at":"2026-09-27T00:46:44Z","board_verified":true,"closed_at":null,"days_open":18,"trust":{"level":"ok","repost_count":null,"flags":[],"days_open":18},"description":"Why Join GEICO?\nAt GEICO, we offer a rewarding career where your ambitions are met with endless possibilities.\nEvery day we honor our iconic brand by offering quality coverage to millions of customers and being there when they need us most. We thrive on relentless innovation to exceed our customers' expectations while making a real impact on local communities nationwide.\nFounded in 1936, GEICO is a member of the Berkshire Hathaway family of companies and one of the largest auto insurers in the United States. When you join our company, we want you to feel valued, supported, and proud to work here. That's why we offer the GEICO Pledge: Great Company, Great Culture, Great Rewards, and Great Careers.\nGEICO is seeking an Identity Security Distinguished Engineer to provide security specific strategic and technical direction for our identity and access management solutions with our user, development and production domains. This individual will play a lead role within GEICO’s Cybersecurity team, with a focus on defensive and protective controls, compliance and governance automation and driving modernization in our identity strategy.\nOur Distinguished Engineer will be the technical and engineering lead for a team of engineers who proactively and holistically deliver secure IAM configuration, threat detection, strategic partnership on the IAM roadmap and create automated proof and validation of our controls. You will help our business transformation as we transition from a traditional IT Security model to a tech organization with engineering excellence as its mission, while co-creating a culture of leveraging security to enable the business and protecting against the latest threats.\nYou will innovate and lead new initiatives, improve Security, enhance existing systems while also identifying new opportunities with an offensive security mindset to find critical problems and solve at a rapid pace. You will help lead the confirmation our systems are protected through automated testing and continuous improvement to raise the bar and foster a proactive security culture which also enables the business without impact. The ideal candidate has deep technical expertise in this domain and an attacker/defender adversarial background.\nAs a Distinguished Engineer, you will:\nInfluence and educate staff at all levels to bring a security minded approach to difficult challenges balancing usability and security.\n\nProvide technical guidance and mentorship to the team, fostering a culture of innovation, collaboration, and continuous improvements.\n\nCollaborate with cross-functional leaders, team members, IAM engineering, and peer security teams to solve complex problems with minimal business impact.\n\nProactively identify opportunities to enhance security measures, streamline processes, and optimize tooling to fortify our environment against emerging threats.\n\nDeliver automation initiatives, conduct advanced research, and develop proofs of concept to enhance our security capabilities and improve overall efficiency.\n\nHelp develop and implement engineered automation to ensure compliance with industry regulations and frameworks which demonstrates without manual efforts.\n\nWork with our business partners to help derive and validate mitigation techniques for identified threats and/or non-compliance.\n\nDefine roadmaps for securing various identities with purposeful and functional security without impacting or unnecessary overhead.\n\nAutomated adversarial testing of our identity systems to ensure detection mechanisms function appropriately and efficiently.\n\nProvide motivating demonstrations and communications to show the value of our security measures to the business, highlighting the low impact on systems, improved operability and resiliency.\n\nQualifications\nExtensive experience in identity products and protocols products Active Directory, Kerberos, LDAP, SAML, SCIM, OAuth, and OIDC.\n\nDeep skills in privileged access management tools and services (build/buy).\n\nExtensive experience in offensive and defensive security roles, with a strong hacker mindset.\n\nExperience building and designing (architecture, design patterns, reliability, and scaling) of security systems with micro-services and extensible REST APIs.\n\nExperience communicating and presentation to senior and junior staff with the ability to influence stakeholders.\n\nExperience in a multi-platform environment with Linux, Mac, Windows.\n\nExperience with multiple IaaS platforms from top tier providers.\n\nExperience with solving security control requirements with engineering approaches.\n\nAbility to excel in a fast-paced, startup-like environment.\n\nAbility to design, perform experiments, and influence security detection and protection solutions.\n\nStrong knowledge of industry-standard security tools, frameworks, and best practices including ITDR, EPM, MITRE, CIS and NIST.\n\nDemonstrated fluency and specialization with at least one modern language such as Python or Go.\n\nIn depth expertise in cryptographic protocols, digital certificates, and encryption standards such as X.509, Transport Layer Security (TLS), and Advanced Encryption Standard (AES).\n\nExperience working with auditors and demonstrating security controls.\n\nExperience\n8+ years in a dedicated security role, preferably in the tech industry\n\n5+ years of experience with security, identity, architecture, and design\n\n5+ years of experience with open-source frameworks is desired.\n\n3+ years of experience with AWS, GCP, Azure, or other cloud providers\n\n3+ years in a senior security role, preferably architecture, influencing company direction on security strategy.\n\nEducation with practical examples in penetration testing, writing test scripts and determining countermeasures.\n\nExperience applying security controls to exceed third party attestation requirements (PCI, SOC, …).\n\nDesired certifications: CISSP, CISA, CISM, CCSK, CCSP, CEH, C|CISO and related GIAC.\n\nEducation\nBachelor’s degree in Computer Science, Cyber Security, or equivalent education with work experience\n\nThird party certifications on penetration testing/ethical hacking, exploit detection and evasion techniques, and related.\n\nAnnual Salary\n$140,000.00 - $300,000.00The above annual salary range is a general guideline. Multiple factors are taken into consideration to arrive at the final hourly rate/ annual salary to be offered to the selected candidate. Factors include, but are not limited to, the scope and responsibilities of the role, the selected candidate’s work experience, education and training, the work location as well as market and business considerations.\nGEICO will consider sponsoring a new qualified applicant for employment authorization for this position.The GEICO Pledge:\nGreat Company: Protecting customers through life’s twists and turns with innovation and integrity.\nGreat Careers: Personalized development programs, mentorship, and certification assistance.\nGreat Culture: Inclusive and collaborative culture rooted in shared success.\nGreat Rewards: Competitive pay, benefits, and flexibility to support your well-being and future.\nThe equal employment opportunity policy of the GEICO Companies provides for a fair and equal employment opportunity for all associates and job applicants regardless of race, color, religious creed, national origin, ancestry, age, gender, pregnancy, sexual orientation, gender identity, marital status, familial status, disability or genetic information, in compliance with applicable federal, state and local law. GEICO hires and promotes individuals solely on the basis of their qualifications for the job to be filled.\nGEICO reasonably accommodates qualified individuals with disabilities to enable them to receive equal employment opportunity and/or perform the essential functions of the job, unless the accommodation would impose an undue hardship to the Company. This applies to all applicants and associates. GEICO also provides a work environment in which each associate is able to be productive and work to the best of their ability. We do not condone or tolerate an atmosphere of intimidation or harassment. We expect and require the cooperation of all associates in maintaining an atmosphere free from discrimination and harassment with mutual respect by and for all associates and applicants.","description_format":"text","description_chars":8296,"description_truncated":false,"requirements":{"experience_years_min":8,"management_years_min":null,"team_size_min":null,"manages_managers":false,"education":{"level":"bachelor","optional":false},"security_clearance":false,"languages":[]},"benefits":[],"hiring_locations":[],"hiring_excludes":[],"relocation_offered":false,"industries":["Property & Casualty Insurance"],"lifecycle":[{"event":"open","at":"2026-09-23T14:46:33Z"}],"liveness":{"score":52,"band":"ok","label":"Likely open","p_open":1,"p_active":0.581,"p_room":0.9,"age_days":17,"expected_fill_days":27,"reasons":["conf:0","stale_co","velocity","win:mid","comp:brand"],"computed_at":"2026-09-26T05:45:00Z"},"pay":{"stated_usd_annual":300000,"is_top_pay":true},"html_url":"https://alion.io/job/geico-identity-security-distinguished-engineer","json_url":"https://alion.io/job/geico-identity-security-distinguished-engineer.json","meta":{"generated_at":"2026-09-27T02:25:43Z","cache_seconds":300,"methodology":"https://alion.io/methodology","terms":"https://alion.io/terms","contact":"https://alion.io/contact","api":"https://alion.io/developers","usage":{"tier":"crawler","counted_by":"address","units_charged":1,"used_today":2162,"day_limit":5000,"remaining_today":2838,"minute_limit":60,"resets_at":"2026-09-28T00:00:00Z"}}}